VDB
Sign up
—

GO-2022-1043

Hardcoded hashed password in github.com/flyteorg/flyteadmin

Quick fix

GO-2022-1043 — github.com/flyteorg/flyteadmin: upgrade to the fixed version with the command below.

go get github.com/flyteorg/flyteadmin@v1.1.44

Details

Default authorization server's configuration settings contain a known hardcoded hashed password.

Users who enable auth but do not override this setting may unknowingly allow public traffic in by way of this default password with attackers effectively impersonating propeller.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/flyteorg/flyteadmin
Introduced in: 1.0.0Fixed in: 1.1.44
Fixgo get github.com/flyteorg/flyteadmin@v1.1.44

References